Zen Cart Logo
Forums / Zen Cart Release Announcements / v1.3.5 Security Alert

v1.3.5 Security Alert

Locked

Views: 18,878

Results 1 to 2 of 2
This thread is locked. New replies are disabled.
2 Oct 2006, 12:31 AM
#1
wilt avatar

wilt

Oji-san

Join Date:
Jun 2003
Location:
Newcastle UK
Posts:
1,865
Plugin Contributions:
3

v1.3.5 Security Alert

We were informed recently of an XSS exploit in Zen Cart code.

I would like to thank Armorize technologies for responding so quickly to clarify the details of the exploit, especially Wayne Huang and Benson Wu of Armorize Technologies,

You can read more about the exploit and how to patch the files that are vulnerable at

http://www.zen-cart.com/forum/showthread.php?p=270700#post270700

2 Oct 2006, 4:51 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: v1.3.5 Security Alert

**Zen Cart v1.3.5 XSS PATCH Released Oct 1, 2006

To combat a reported XSS exploit vulnerability in Zen Cart, simply download the files from the patch ZIP and copy the enclosed /admin files for login.php and password_forgotten.php to your admin folder.

Remember, if you have renamed your admin folder, you will have to use that
folder name when copying/uploading.**

File can be downloaded here:
http://sourceforge.net/project/showfiles.php?group_id=83781&package_id=171544&release_id=444622

These fixes are NOT included in the main "full-fileset" zip.
Please apply these fixes AFTER unzipping the main full-fileset zip contents.

Alternatively, you may wish to apply the edits manually:
http://www.zen-cart.com/forum/showthread.php?t=47526